Privacy Policy
Last updated: March 6, 2026
1. Data Controller
The data controller responsible for your personal data is ScriptDoctor, operating at scriptdoctor.pro, EU, Poland ("Controller", "we", "us", "our"). The Controller is in the process of registering a formal business entity; this Policy will be updated with registered entity details upon completion.
For any questions regarding data protection, contact us at: support@scriptdoctor.pro
2. Information We Collect
2.1 Screenplay Content
The scripts and screenplays you upload for analysis. This content is processed in real-time and is not permanently stored on our servers (see Section 4 for details).
2.2 Payment Information
When you purchase a paid tier, payment is processed by Stripe, Inc. We receive a transaction confirmation, your email address, and a truncated card reference from Stripe. We do not receive or store your full credit card number, CVV, or other sensitive payment credentials.
2.3 Technical Data
We automatically collect: IP address, browser type and version, operating system, device type, referring URL, pages viewed, time and date of access, and session duration. This data is collected through server logs and analytics tools.
2.4 Contact Information
If you contact us for support, we collect your email address and any information you voluntarily provide in your communication.
2.5 Cookie Data
We collect data through cookies and similar technologies as described in our separate Cookie Policy.
3. Legal Basis for Processing (GDPR Article 6)
We process your personal data on the following legal bases:
- Performance of a contract (Art. 6(1)(b)): Processing screenplay content to deliver the analysis service you requested; processing payment data to complete your purchase; providing customer support in connection with the Service.
- Legitimate interest (Art. 6(1)(f)): Collecting technical data for security, fraud prevention, and Service stability; analyzing aggregated, anonymized usage patterns to improve Service quality and user experience; maintaining server logs for debugging and performance monitoring.
- Legal obligation (Art. 6(1)(c)): Retaining transaction records as required by applicable tax and accounting regulations.
- Consent (Art. 6(1)(a)): Placing non-essential cookies on your device (analytics cookies); any future marketing communications, if applicable. You may withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal.
4. Screenplay Data Handling
- No permanent storage on our servers: Your PDF is parsed in memory and never written to disk or any database on our infrastructure. The extracted text is transmitted to Anthropic (our AI provider) via encrypted API calls for real-time analysis, then discarded. After the Report is generated, the screenplay text exists only in your browser's local storage for up to 24 hours. Anthropic may retain API inputs for up to 30 days for trust & safety monitoring purposes per their Privacy Policy, after which they are deleted.
- No AI training: We do not use your screenplay content to train, fine-tune, or improve any AI models. Anthropic's API terms likewise prohibit using API inputs to train their models; your screenplay is not used to improve Claude or any other Anthropic system.
- No human review: Your screenplay content is not reviewed, read, or accessed by any human employee, contractor, or agent of ScriptDoctor, except in cases where you explicitly request technical support and provide consent for such review.
- Aggregated metrics only: We may collect anonymized, aggregated statistical data about Service usage that cannot be used to identify you or reconstruct any portion of your screenplay content.
5. Data Retention Periods
- Screenplay content: Not permanently stored. Processed in real-time and discarded upon completion of analysis.
- Analysis Reports: Available in your browser session. Not stored on our servers after delivery.
- Payment records: Transaction records retained for 5 years as required by Polish tax regulations.
- Technical/server logs: Retained for up to 90 days, then automatically deleted.
- Support communications: Retained for up to 2 years after the last communication.
- Cookie data: Retention periods vary by cookie type; see our Cookie Policy for details.
6. International Data Transfers
- Anthropic, PBC (United States): Screenplay content transmitted for AI analysis. Transfer mechanism: Standard Contractual Clauses (SCCs) and/or Anthropic's Data Processing Addendum.
- Stripe, Inc. (United States): Payment data processed by Stripe. Transfer mechanism: Stripe's compliance with EU-US Data Privacy Framework and Standard Contractual Clauses.
- Vercel, Inc. (United States/Global): Hosting and content delivery. Transfer mechanism: Standard Contractual Clauses and Vercel's Data Processing Agreement.
7. Your Rights Under GDPR
Under applicable data protection law, you have the following rights:
- Right of access (Art. 15): Request a copy of the personal data we hold about you.
- Right to rectification (Art. 16): Request correction of inaccurate personal data.
- Right to erasure (Art. 17): Request deletion of your personal data ("right to be forgotten").
- Right to restriction (Art. 18): Request that we limit the processing of your personal data.
- Right to data portability (Art. 20): Receive your data in a structured, machine-readable format.
- Right to object (Art. 21): Object to processing based on legitimate interests.
- Right to withdraw consent (Art. 7(3)): Withdraw consent at any time for consent-based processing.
- Right to lodge a complaint: You may lodge a complaint with the Polish data protection authority (UODO) at uodo.gov.pl.
To exercise any of these rights, contact us at support@scriptdoctor.pro. We will respond within 30 days.
8. Automated Decision-Making and Profiling
The Service uses automated processing (AI analysis) under GDPR Article 22. The analysis Report is advisory in nature and does not produce legal or similarly significant effects on you.
9. Children's Privacy
The Service is not directed to individuals under 18. If you believe a child has submitted personal data through our Service, please contact support@scriptdoctor.pro and we will promptly delete that data.
10. Data Security
Our security measures include: HTTPS/TLS 1.2+ encryption for all data in transit; use of security-audited third-party providers; access controls limiting who can access data; and no permanent screenplay storage on our infrastructure.
11. Third-Party Services
- Anthropic: anthropic.com/privacy
- Stripe: stripe.com/privacy
- Vercel: vercel.com/legal/privacy-policy
12. California Privacy Rights (CCPA/CPRA)
California residents have the following rights:
- Right to know what personal information is collected and how it is used
- Right to delete personal information
- Right to opt-out of the sale of personal information (we do not sell personal information)
- Right to non-discrimination for exercising privacy rights
13. Do Not Track Signals
The Service currently does not respond to DNT browser signals. You can control tracking through our Cookie consent mechanism on this site.
14. Data Breach Notification
In the event of a personal data breach, we will notify the Polish data protection authority (UODO) within 72 hours as required by GDPR Article 33. If the breach is likely to result in a high risk to your rights and freedoms, we will notify you directly without undue delay (GDPR Article 34).
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. For material changes, we will notify affected users by email at least 30 days before the changes take effect.
16. Contact Information
- Data Protection: support@scriptdoctor.pro
- General Support: support@scriptdoctor.pro